Menu

#212 CVE-2024-47554 reported against commons-io shaded in velocity

All
closed-fixed
nobody
None
5
2025-05-21
2025-04-29
No

yajsw-stable-13.14/lib/extended/velocity/velocity-engine-core-2.3.jarcontains shaded classes from commons-io that contain a vulnerability.
The shaded classes were removed in Velocity 2.4 (and the current version 2.4.1) as per https://issues.apache.org/jira/browse/VELOCITY-972. Please update the dependency.

Discussion

  • rzo

    rzo - 2025-05-21
    • status: open --> closed-fixed
     
  • rzo

    rzo - 2025-05-21

    release 13.15

     

Log in to post a comment.